[
https://issues.apache.org/jira/browse/FLINK-5981?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15899651#comment-15899651
]
ASF GitHub Bot commented on FLINK-5981:
---------------------------------------
Github user StephanEwen commented on a diff in the pull request:
https://github.com/apache/flink/pull/3486#discussion_r104704130
--- Diff:
flink-runtime/src/main/java/org/apache/flink/runtime/net/SSLUtils.java ---
@@ -55,6 +58,42 @@ public static boolean getSSLEnabled(Configuration
sslConfig) {
}
/**
+ * Sets SSl version and cipher suites for SSLServerSocket
+ * @param socket
+ * Socket to be handled
+ * @param config
+ * The application configuration
+ */
+ public static void setSSLVerAndCipherSuites(ServerSocket socket,
Configuration config) {
+ if (socket instanceof SSLServerSocket) {
+ ((SSLServerSocket)
socket).setEnabledProtocols(config.getString(
+ ConfigConstants.SECURITY_SSL_PROTOCOL,
+
ConfigConstants.DEFAULT_SECURITY_SSL_PROTOCOL).split(","));
--- End diff --
simply calling `split()` on a config value may lead to errors with bad
error messages when the config value is misconfigured. I think it would be nice
to do some more explicit handling here.
> SSL version and ciper suites cannot be constrained as configured
> ----------------------------------------------------------------
>
> Key: FLINK-5981
> URL: https://issues.apache.org/jira/browse/FLINK-5981
> Project: Flink
> Issue Type: Bug
> Components: Security
> Reporter: Tao Wang
> Assignee: Tao Wang
>
> I configured ssl and start flink job, but found configured properties cannot
> apply properly:
> akka port: only ciper suites apply right, ssl version not
> blob server/netty server: both ssl version and ciper suites are not like what
> I configured
> I've found out the reason why:
> http://stackoverflow.com/questions/11504173/sslcontext-initialization (for
> blob server and netty server)
> https://groups.google.com/forum/#!topic/akka-user/JH6bGnWE8kY(for akka ssl
> version, it's fixed in akka 2.4:https://github.com/akka/akka/pull/21078)
> I'll fix the issue on blob server and netty server, and it seems like only
> upgrade for akka can solve issue in akka side(we'll consider later as upgrade
> is not a small action).
--
This message was sent by Atlassian JIRA
(v6.3.15#6346)